4.3
CVE-2006-2088
- EPSS 1.06%
- Veröffentlicht 29.04.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:19
- Erkennungen
Multiple cross-site scripting (XSS) vulnerabilities in Devsyn Open Bulletin Board (OpenBB) 1.0.6 allow remote attackers to inject arbitrary web script or HTML via (1) the FID parameter in board.php and (2) the TID parameter in read.php. NOTE: the SQL injection issues are already covered by CVE-2005-1612 (read.php) and CVE-2005-2566 (board.php).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Devsyn ≫ Open Bulletin Board Version 1.0.6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.06% | 0.6 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://securityreason.com/securityalert/806
http://www.securityfocus.com/archive/1/432106/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/26095